Recently I participated in Etsy Bug Bounty Program and got success for a long time working and now I'm in Etsy Hall Of Fame for reporting Vulnerabilities to them:
http://www.etsy.com/help/article/2463
Showing posts with label Bug Bounty. Show all posts
Showing posts with label Bug Bounty. Show all posts
Twitter - White Hat Program
Long time ago , I was found a bug in Twitter acquired site https://bagcheck.com/ , and I reported a bug to Twitter and they confirmed this issue. After some months Twitter asked me to prefer name for Twitter White Hat List and Updated me in their White Hat List.
https://about.twitter.com/company/security
https://about.twitter.com/company/security
Facebook HTML Injection
Found a Bug in Facebook
Hello,
I discovered a Html Injection in m.facebook.com.
Here is a Vulnerable Page.
I changed the value of parameter error , to Bug Found By ALi Hasan Ghauri
Link:https://m.facebook.com/pages/boosted_post/?pid=154728514671464&sid=317138311763816&
error=Bug%20Found%20By%20ALi%20Hasan%20Ghauri
Now See
Facebook accepted this bug.
And The Bounty Reward
Thanks Facebook Security Team !!!
Ali Hasan Ghauri In Wizehive Special_Thanks Page !
Well , WizeHive empowers people to get customized business applications up and
running in under an hour. These business applications gather any type of
data and get work done efficiently.
WizeHive is honored to spotlight the Reearchers for their contributions in making WizeHive safer and their actions benefit the thousands of people who rely on WizeHive every day.
Ali Hasan Ghauri In Wizehive Special_Thanks Page :
http://www.wizehive.com/special_thanks.html
He Got this by reporting two Cross Site Scripting to them :
ALHAMDULILLAH !
WizeHive is honored to spotlight the Reearchers for their contributions in making WizeHive safer and their actions benefit the thousands of people who rely on WizeHive every day.
Ali Hasan Ghauri In Wizehive Special_Thanks Page :
http://www.wizehive.com/special_thanks.html
He Got this by reporting two Cross Site Scripting to them :
ALHAMDULILLAH !
"Grand Stand 4" [Design for Trade Fair Stands] worth € 69.00 | ALHAMDULILLAH !
Hi Every One ,
Today is the Awesome Day , Because i just received a 3.0 Kg of Book "Grand Stand 4" [Design for Trade Fair Stands] worth € 69.00 as a reward from Frameweb.com . I was reported some Vulnerabilities to them . Then they replied me (as shown in Screen Shot) .
Have a Look .
Here's the Link : http://www.frameweb.com/books/grand-stand-4
And a Caption.
The weight of this Book is 3.0 Kg and this Book is the latest title in the Grand Stand series presents recent developments in the ever-changing world of stand design.
Today is the Awesome Day , Because i just received a 3.0 Kg of Book "Grand Stand 4" [Design for Trade Fair Stands] worth € 69.00 as a reward from Frameweb.com . I was reported some Vulnerabilities to them . Then they replied me (as shown in Screen Shot) .
Have a Look .
Here's the Link : http://www.frameweb.com/books/grand-stand-4
And a Caption.
The weight of this Book is 3.0 Kg and this Book is the latest title in the Grand Stand series presents recent developments in the ever-changing world of stand design.
![]() |
| Grand-Stand-4 |
Thanks to the Frameweb Team
Listed as Responsible disclosure in wizehive.com
WizeHive is honored to spotlight the following people for their
contributions in making WizeHive safer. Members of this list reported
significant bugs or security concerns, and their actions benefit the
thousands of people who rely on WizeHive every day.
Ali Hasan Ghauri (@alihasanghauri)
On behalf of the WizeHive team and users worldwide, thank you.
Ali Hasan Ghauri (@alihasanghauri)
On behalf of the WizeHive team and users worldwide, thank you.
Ali Hasan Ghauri , Listed in Ebay Responsible Disclosure Acknowledgements
14 Years old , The Youngest Security Researcher " Ali Hasan Ghauri " founder of AHPT have Listed in Ebay
Responsible Disclosure Acknowledgements
ChinaBuye Gives " Ali Hasan Ghauri "(AHPT) 500 Points For reporting Some Bugs .
China Buye Gives Me 500 Points For reporting Some Bugs .
i can buy Redeem Things with this Points .
I already bought a Watch at 251 Points !!! Waiting for receiving .
My remaining Points is 249 , !!! I enjoying !!!
Now it's Your turn . Keep Trying for finding bugs on http://www.chinabuye.com/ .
Security Researchers Acknowledgment
Facebook - White Hats
https://www.facebook.com/whitehat/
Twitter - Twitter Whitehats 2012 & 2013
https://twitter.com/about/security
Google - Security Hall of Fame - Honorable Mention - "April - June 2011"
http://www.google.com/about/appsecurity/hall-of-fame/distinction/
Tuenti - Security Hall of Fame
http://corporate.tuenti.com/en/dev/hall-of-fame
Nokia Siemens Networks - Security Hall of Fame - "November 2012"
http://www.nokiasiemensnetworks.com/about-us/responsible-disclosure
Constant Contact - Security Acknowledgement
http://www.constantcontact.com/about-constant-contact/security/report-vulnerability.jsp
OwnCloud - Security Hall of Fame 2012 & 2013
http://owncloud.org/security/hall-of-fame/
iFixit - Security Acknowledgement 2012 & 2013
http://www.ifixit.com/Info/responsible_disclosure
Zynga - Whitehats 2012 & 2013
http://company.zynga.com/security/whitehats
Redhat - Vulnerability Acknowledgements for Redhat online services -"2012 Acknowledgements"
https://access.redhat.com/knowledge/articles/66234
Adobe - Security Acknowledgments
http://www.adobe.com/support/security/bulletins/securityacknowledgments.html
SoundCloud - Whitehat Thanks List
http://help.soundcloud.com/customer/portal/articles/439715-responsible-disclosure
GitLab - Vulnerability Acknowledgements
http://blog.gitlab.com/vulnerability-acknowledgements/
Collective Idea - HarmonyApp Security Thank-you List
http://get.harmonyapp.com/security/
https://www.facebook.com/whitehat/
Twitter - Twitter Whitehats 2012 & 2013
https://twitter.com/about/security
Google - Security Hall of Fame - Honorable Mention - "April - June 2011"
http://www.google.com/about/appsecurity/hall-of-fame/distinction/
Tuenti - Security Hall of Fame
http://corporate.tuenti.com/en/dev/hall-of-fame
Nokia Siemens Networks - Security Hall of Fame - "November 2012"
http://www.nokiasiemensnetworks.com/about-us/responsible-disclosure
Constant Contact - Security Acknowledgement
http://www.constantcontact.com/about-constant-contact/security/report-vulnerability.jsp
OwnCloud - Security Hall of Fame 2012 & 2013
http://owncloud.org/security/hall-of-fame/
iFixit - Security Acknowledgement 2012 & 2013
http://www.ifixit.com/Info/responsible_disclosure
Zynga - Whitehats 2012 & 2013
http://company.zynga.com/security/whitehats
Redhat - Vulnerability Acknowledgements for Redhat online services -"2012 Acknowledgements"
https://access.redhat.com/knowledge/articles/66234
Adobe - Security Acknowledgments
http://www.adobe.com/support/security/bulletins/securityacknowledgments.html
SoundCloud - Whitehat Thanks List
http://help.soundcloud.com/customer/portal/articles/439715-responsible-disclosure
GitLab - Vulnerability Acknowledgements
http://blog.gitlab.com/vulnerability-acknowledgements/
Collective Idea - HarmonyApp Security Thank-you List
http://get.harmonyapp.com/security/
Bug Bounty Programs
List of Bug Bounty Programs
Bug Bounty Program a well known topic is on the heat these days, known companies like: google, Facebook, Mozilla are paying for finding a vulnerabilities on their web servers, products, services or some associated applications. Here is a list for all the Security Researchers and Bug Hunters to target all the best :)
Bug Bounty Websites for Web Application Vulnerability
Mozilla
security@mozilla.org
http://www.mozilla.org/security
http://www.mozilla.org/projects/security/security-bugs-policy.html
http://www.mozilla.org/security/announce
Google
security@google.com
https://www.google.com/appserve/security-bugs/new?rl=xkp7zert49a5q6owod28bhr2
Facebook
http://www.facebook.com/whitehat/bounty
Paypal
sitesecurity@paypal.com
https://cms.paypal.com/cgi-bin/marketingweb?cmd=_render-content&content_ID=security/reporting_security_issues
Etsy
http://www.etsy.com
Wordpress
http://www.whitefirdesign.com/about/wordpress-security-bug-bounty-program.html
Commonsware
http://commonsware.com/bounty.html
CCBill
http://www.ccbill.com/developers/security/vulnerability-reward-program.php
http://www.ccbill.com/developers/security/rewards.php
Vark
http://www.vark.com
Windthorstisd
http://www.windthorstisd.net/BugReport.cfm
Bug Bounty Websites for Products Vulnerability
Mozilla
http://www.mozilla.org/security
http://www.mozilla.org/security/known-vulnerabilities/firefox.html
Google Chrome
http://www.chromium.org/Home/chromium-security/vulnerability-rewards-program
Zero Day Initiative
http://www.zerodayinitiative.com
Barracuda
bugbounty@barracuda.com
http://www.barracudalabs.com/bugbounty
http://www.barracudalabs.com/bugbounty/halloffame.html
Artifex Software
http://www.ghostscript.com/Bug_bounty_program.html
Hex Rays
http://www.hex-rays.com/bugbounty.shtml
Ardour
http://ardour.org/bugbounty
Piwik
http://piwik.org/security
Hall of Fame & Responsible Disclosure Websites(No Bounties)
Microsoft
http://technet.microsoft.com/en-us/security/ff852094.aspx
http://technet.microsoft.com/en-us/security/cc308589
http://technet.microsoft.com/en-us/security/cc308575
http://technet.microsoft.com/en-us/security/cc261624
http://www.microsoft.com/security/msrc/default.aspx
Apple
product-security@apple.com
http://support.apple.com/kb/HT1318
https://ssl.apple.com/support/security/
Adobe
http://www.adobe.com/support/security/bulletins/securityacknowledgments.html
http://www.adobe.com/support/security/alertus.html
IBM
http://www-03.ibm.com/security/secure-engineering/report.html
Twitter
https://twitter.com/about/security
http://support.twitter.com/groups/33-report-abuse-or-policy-violations/topics/122-reporting-violations/articles/477159-how-to-report-xss-api-and-other-security-vulnerabilities#
https://support.twitter.com/forms
Dropbox
security@dropbox.com
https://www.dropbox.com/security
https://www.dropbox.com/special_thanks
Cisco
http://tools.cisco.com/security/center/home.x#~alerts
Moodle
http://moodle.org/security
Drupal
http://drupal.org/security-team
Oracle
http://www.oracle.com/us/support/assurance/reporting/index.html
Symantec
http://www.symantec.com/security
Ebay
http://pages.ebay.com/securitycenter/Researchers.html
Twilio
http://www.twilio.com/blog/2012/03/reporting-security-vulnerabilities.html
37 Signals
http://37signals.com/security-response
Salesforce
http://www.salesforce.com/company/privacy/disclosure.jsp
Reddit
http://code.reddit.com/wiki/help/whitehat
Github
http://help.github.com/responsible-disclosure/
Ifixit
http://www.ifixit.com/Info/responsible_disclosure
Constant Contact
http://www.constantcontact.com/about-constant-contact/security/report-vulnerability.jsp
Zeggio
http://www.zeggio.com
Simplify
http://simplify-llc.com/simplify-security.html
Team Unify
http://www.teamunify.com/__corp__/security.php
Skoodat
http://www.skoodat.com/Security
Relaso
http://relaso.com/disclosure
Moduscsr
http://www.moduscsr.com/security_statement.php
Cloudnetz
http://cloudnetz.com/Legal/vulnerability-testing-policy.html
Emptrust
http://www.emptrust.com/Security.aspx
Apriva
http://www.apriva.com/security
Amazon
http://aws.amazon.com/security/vulnerability-reporting
SqaureUp
https://squareup.com/security/levels
G-Sec
http://www.g-sec.lu/responsible.disclosure.policy.html
Xen
http://www.xen.org/projects/security_vulnerability_process.html
Engine Yard
http://www.engineyard.com/legal/responsible-disclosure-policy
Lastpass
https://lastpass.com/support_security.php
RedHat
https://access.redhat.com/knowledge/articles/66234
Acquia
https://www.acquia.com/how-report-security-issue
Mahara
security@mahara.org
https://wiki.mahara.org/index.php/Security
Zynga
security@zynga.com
http://company.zynga.com/security/whitehats
Risk.io
https://www.risk.io/security
Opera
http://www.opera.com/security/policy
Owncloud
http://owncloud.org/security/policy
http://owncloud.org/security/hall-of-fame
Scorpion Soft
security@scorpionsoft.com
http://www.scorpionsoft.com/company/disclosurepolicy
Cpaperless
http://www.cpaperless.com/securitystatement.aspx
Wizehive
http://www.wizehive.com/security
Tuenti
http://corporate.tuenti.com/en/dev/hall-of-fame
Nokia Siemens
http://www.nokiasiemensnetworks.com/about-us/responsible-disclosure
Sound Cloud
http://help.soundcloud.com/customer/portal/articles/439715-responsible-disclosure
HTC
http://www.htc.com/us/legal/product-security
Neohapsis
http://www.neohapsis.com/disclosure.php
Puppetlabs
http://puppetlabs.com/security
Norada
http://norada.com/norada/crm/security_response
Bug Bounty Program a well known topic is on the heat these days, known companies like: google, Facebook, Mozilla are paying for finding a vulnerabilities on their web servers, products, services or some associated applications. Here is a list for all the Security Researchers and Bug Hunters to target all the best :)
Bug Bounty Websites for Web Application Vulnerability
Mozilla
security@mozilla.org
http://www.mozilla.org/security
http://www.mozilla.org/projects/security/security-bugs-policy.html
http://www.mozilla.org/security/announce
security@google.com
https://www.google.com/appserve/security-bugs/new?rl=xkp7zert49a5q6owod28bhr2
http://www.facebook.com/whitehat/bounty
Paypal
sitesecurity@paypal.com
https://cms.paypal.com/cgi-bin/marketingweb?cmd=_render-content&content_ID=security/reporting_security_issues
Etsy
http://www.etsy.com
Wordpress
http://www.whitefirdesign.com/about/wordpress-security-bug-bounty-program.html
Commonsware
http://commonsware.com/bounty.html
CCBill
http://www.ccbill.com/developers/security/vulnerability-reward-program.php
http://www.ccbill.com/developers/security/rewards.php
Vark
http://www.vark.com
Windthorstisd
http://www.windthorstisd.net/BugReport.cfm
Bug Bounty Websites for Products Vulnerability
Mozilla
http://www.mozilla.org/security
http://www.mozilla.org/security/known-vulnerabilities/firefox.html
Google Chrome
http://www.chromium.org/Home/chromium-security/vulnerability-rewards-program
Zero Day Initiative
http://www.zerodayinitiative.com
Barracuda
bugbounty@barracuda.com
http://www.barracudalabs.com/bugbounty
http://www.barracudalabs.com/bugbounty/halloffame.html
Artifex Software
http://www.ghostscript.com/Bug_bounty_program.html
Hex Rays
http://www.hex-rays.com/bugbounty.shtml
Ardour
http://ardour.org/bugbounty
Piwik
http://piwik.org/security
Hall of Fame & Responsible Disclosure Websites(No Bounties)
Microsoft
http://technet.microsoft.com/en-us/security/ff852094.aspx
http://technet.microsoft.com/en-us/security/cc308589
http://technet.microsoft.com/en-us/security/cc308575
http://technet.microsoft.com/en-us/security/cc261624
http://www.microsoft.com/security/msrc/default.aspx
Apple
product-security@apple.com
http://support.apple.com/kb/HT1318
https://ssl.apple.com/support/security/
Adobe
http://www.adobe.com/support/security/bulletins/securityacknowledgments.html
http://www.adobe.com/support/security/alertus.html
IBM
http://www-03.ibm.com/security/secure-engineering/report.html
https://twitter.com/about/security
http://support.twitter.com/groups/33-report-abuse-or-policy-violations/topics/122-reporting-violations/articles/477159-how-to-report-xss-api-and-other-security-vulnerabilities#
https://support.twitter.com/forms
Dropbox
security@dropbox.com
https://www.dropbox.com/security
https://www.dropbox.com/special_thanks
Cisco
http://tools.cisco.com/security/center/home.x#~alerts
Moodle
http://moodle.org/security
Drupal
http://drupal.org/security-team
Oracle
http://www.oracle.com/us/support/assurance/reporting/index.html
Symantec
http://www.symantec.com/security
Ebay
http://pages.ebay.com/securitycenter/Researchers.html
Twilio
http://www.twilio.com/blog/2012/03/reporting-security-vulnerabilities.html
37 Signals
http://37signals.com/security-response
Salesforce
http://www.salesforce.com/company/privacy/disclosure.jsp
http://code.reddit.com/wiki/help/whitehat
Github
http://help.github.com/responsible-disclosure/
Ifixit
http://www.ifixit.com/Info/responsible_disclosure
Constant Contact
http://www.constantcontact.com/about-constant-contact/security/report-vulnerability.jsp
Zeggio
http://www.zeggio.com
Simplify
http://simplify-llc.com/simplify-security.html
Team Unify
http://www.teamunify.com/__corp__/security.php
Skoodat
http://www.skoodat.com/Security
Relaso
http://relaso.com/disclosure
Moduscsr
http://www.moduscsr.com/security_statement.php
Cloudnetz
http://cloudnetz.com/Legal/vulnerability-testing-policy.html
Emptrust
http://www.emptrust.com/Security.aspx
Apriva
http://www.apriva.com/security
Amazon
http://aws.amazon.com/security/vulnerability-reporting
SqaureUp
https://squareup.com/security/levels
G-Sec
http://www.g-sec.lu/responsible.disclosure.policy.html
Xen
http://www.xen.org/projects/security_vulnerability_process.html
Engine Yard
http://www.engineyard.com/legal/responsible-disclosure-policy
Lastpass
https://lastpass.com/support_security.php
RedHat
https://access.redhat.com/knowledge/articles/66234
Acquia
https://www.acquia.com/how-report-security-issue
Mahara
security@mahara.org
https://wiki.mahara.org/index.php/Security
Zynga
security@zynga.com
http://company.zynga.com/security/whitehats
Risk.io
https://www.risk.io/security
Opera
http://www.opera.com/security/policy
Owncloud
http://owncloud.org/security/policy
http://owncloud.org/security/hall-of-fame
Scorpion Soft
security@scorpionsoft.com
http://www.scorpionsoft.com/company/disclosurepolicy
Cpaperless
http://www.cpaperless.com/securitystatement.aspx
Wizehive
http://www.wizehive.com/security
Tuenti
http://corporate.tuenti.com/en/dev/hall-of-fame
Nokia Siemens
http://www.nokiasiemensnetworks.com/about-us/responsible-disclosure
Sound Cloud
http://help.soundcloud.com/customer/portal/articles/439715-responsible-disclosure
HTC
http://www.htc.com/us/legal/product-security
Neohapsis
http://www.neohapsis.com/disclosure.php
Puppetlabs
http://puppetlabs.com/security
Norada
http://norada.com/norada/crm/security_response












![Reward from Frameweb.com to the Student of Class 9th [14 years Boy] Frameweb-Books](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiE7Ahydl7H8ask_pu_pCpIz1vUP5Df2zEJifbKH_LAYXgOafIwsNTZQD9wSqgSNLA1isKC2a55laJ8pFk3eRlpj4rwbZ3K8FPY5lSL30kDNTNtDAYaRQBEx9jiNwFfmhdlBa2GwdSnhA8E/s320/DSC_0249.jpg)












